Skip to content
OnTrackio

Identity

OnTrackio + SAML 2.0 (any IdP)

Generic SAML 2.0 with just-in-time provisioning and role mapping, hardened the paranoid way.

What you get

  • Sign-on from any SAML 2.0 identity provider: Okta, Entra, JumpCloud, Keycloak, and the rest
  • Just-in-time user provisioning on first login, with attribute-driven role mapping you configure per IdP
  • Replay defense, signature-algorithm allowlisting, and strict audience checks by default
  • MFA policy alignment: a misconfigured IdP cannot silently bypass your workspace MFA requirement
  • Single logout, so ending the IdP session ends the workspace session

How it connects

You register your IdP's metadata in the admin console, map the attributes you want carried into user records, and optionally map IdP groups or attributes to roles. The implementation is tested continuously against a real SAML IdP in our test suite, not just against recorded fixtures.

What it deliberately does not do

SAML covers sign-on and just-in-time creation; it does not deprovision. If you want leavers handled automatically, pair it with SCIM, which is the difference explained honestly in the setup guide.

Plan note. SAML 2.0 is an Enterprise-tier feature; Google and Microsoft sign-in cover the other tiers. Pricing is public.

Frequently asked questions

Which identity providers are supported?

Any product that speaks standards-compliant SAML 2.0. Okta and Entra are the ones we document step by step; JumpCloud, Keycloak, OneLogin, and Ping follow the same generic guide. If your IdP produces valid SAML metadata, it connects.

Does SAML handle offboarding?

Not by itself, and any vendor implying otherwise is glossing over the standard. SAML stops a leaver from signing in again once the IdP disables them, but existing sessions and role cleanup are SCIM's job. We support both, and the guide is explicit about which rail does what.

Can SAML users bypass MFA policy?

No. The workspace MFA policy is evaluated on top of SAML sign-on: if your policy requires MFA and the IdP assertion does not demonstrate it, the user completes a local factor. A misconfigured IdP degrades to more security, not less.

All integrations: the full list. Identity posture, sub-processors, and residency: the security page.

See SAML 2.0 (any IdP) connected to a live workspace

A 30-minute demo covers the setup, the day-two behaviour, and the honest boundaries. Public pricing, no discovery-call gauntlet.